CVE-2021-43033: OS Command Injection
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43033?
CVE-2021-43033 is classified as critical due to the potential for arbitrary remote code execution as root.
How do I fix CVE-2021-43033?
To mitigate CVE-2021-43033, you should upgrade the Kaseya Unitrends Backup Appliance to version 10.5.5 or later.
What systems are affected by CVE-2021-43033?
CVE-2021-43033 affects Kaseya Unitrends Backup versions prior to 10.5.5.
What kind of attack can leverage CVE-2021-43033?
CVE-2021-43033 can be exploited to achieve arbitrary remote code execution, allowing attackers to gain root privileges.
What causes the vulnerability in CVE-2021-43033?
The vulnerability in CVE-2021-43033 is caused by untrusted input being passed to system calls in the bpserverd daemon.